CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware

August 14, 2026

Threat actors are increasingly acquiring expired domains—known as “dropcatch domains”—to inherit their reputation and traffic, redirecting victims to scams and malware. According to DNS threat intelligence firm Infoblox, during the first half of 2026, approximately 50,400 dropcatch domains were re-registered daily in gTLDs like “.com,” rising to around 65,000 when ccTLDs are included. These account for nearly 20% of all daily gTLD and ccTLD registrations.

Infoblox identified a major threat actor, dubbed “Sable Squirrel,” which has spent nearly $7 million on expired domains to build a criminal enterprise spanning illegal sports streaming, online gambling promotion, and malware infrastructure. The operation, believed to be based in Vietnam, controls over 10,000 domains, many serving as a backbone for Asian sports piracy brands such as Xoilac, Cakhia, 90phut, Socolive, and MiTom. These platforms funnel users to betting services like VSBet, ColaScore, and 8xbet, while a subset of the domains also function as malware command-and-control (C2) servers. Over 31,000 malware samples, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, njRAT, and HiddenTear ransomware artifacts, have communicated with Sable Squirrel’s infrastructure.

Infoblox is also tracking three other financially motivated “scavenger” actors: Stuffy Squirrel (active since 2020, over 500 domains), Shady Squirrel (active since 2023, over 700 domains), and Swiping Squirrel (active since 2022, over 3,000 domains). These actors acquire expired domains to hijack residual traffic and resell it to affiliate networks, initial access brokers, or zero-click advertising platforms.

The report highlights that 24% of re-registered dropcatch domains go live the same day, 76% within seven days, and 94% within two weeks, underscoring the speed at which these domains are weaponized. Infoblox emphasizes that defenders must not rely solely on domain reputation, as threat actors exploit inherited trust to evade security checks.

Attack groups: Sable Squirrel, Stuffy Squirrel, Shady Squirrel, Swiping Squirrel, SocGholish

Malware: Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, njRAT, HiddenTear

Companies: Infoblox, GoDaddy, Namecheap, DropCatch.com, Dynabot, General Electric, Procter & Gamble, Kroger, Albertsons, Sony, GitLab